CyberRota Analysis
AI-GeneratedThe YayCurrency WordPress plugin prior to version 3.3.5 is vulnerable due to a lack of capability and ownership checks on its multi-vendor integration handlers, which can be accessed by unauthenticated users. This flaw allows attackers to retrieve sensitive information, including order totals and vendors' financial data, by manipulating identifiers. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data exposure.
Original NVD Description
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.